
Gain practical insights in IoT pentest with foundational cybersecurity knowledge and basic Linux command line skills, plus chapter introductions and hands-on hacking challenges to assimilate concepts.
List of operating systems that will be used during exercises, links for downloading, and the recommended way to use them so that you can better follow the exercises and start hacking IoT on your own.
IoT hacking requires specific tools that include hardware and software. In this session, we're going through the minimum and needed hardware tools to do the exercises and to start on IoT hacking, explaining how to use them and why they are essential.
Last session we focused on the hardware side and now we're going to explore the minimum and required software and applications in order to follow the exercises and to start IoT hacking, explanation on how to use and why they are important
A bill of materials or shopping list specific for following the challenges of this course and references on where to buy them.
As soldering is something that every IoT hacker will have to deal with we will provide an introduction to soldering, for a good soldering, explaining why soldering is important for IoT hacking, How to improve soldering skills what is a good soldering and what is a bad soldering and some examples of common soldering used for IoT hacking
Basic lessons on how to proper measure voltage, current, resistance and continuity as this will be an important helper on analyzing signals and to identify pinouts
How to use FCC ID from the device to find essential and useful information about the device even before you open it. How to use datasheets to find out the pinout of chips and an overview of PCI interfaces. Those would be necessary steps during your information-gathering phase.
similar to UART, JTAG interfaces are another common way hackers can interact with an IoT device to get sensitive information. In this session we're going to explain what is a JTAG interface, what it's used for, how to detect it on the PCB, and how to detect it's pinout
Similar to UART, JTAG interfaces are another common way hackers can interact with an IoT device to get sensitive information. In this session we're going to explain what is a JTAG interface, what it's used for, how to detect it on the PCB, and how to detect it's pinout
Exploiting firmware is one of the major parts of an IoT hacker. To gain access to the firmware, we can read it directly from the controller over SPI. In this session, we'll explain what is a SPI interface, what it's used for, how to detect it on the PCB, and how to detect its pinout
To enhance the learning objectives from this chapter, given a specific IoT device that will be referenced, your challenge would be to open it up and find the main chips, components, datasheets, FCC ID, all interfaces, and their Pinout.
Explore hardware hacking by locating the FCC ID and identifying firmware hosting, then connect a UART, verify VCC, use 115200 baud, and extract the firmware for analysis.
The firmware is the "soul" of your IoT device, and there are so many things you can do to exploit your device through the firmware. That's why we will cover here its definition, purpose, and main components like memory, bootloader, filesystem, and familiar OS.
Binwalk is the most popular application for unpacking the firmware and you'll understand why here while we'll be using binwalk and it's basic operations for unpacking firmware and getting access to different file systems of different operating systems
Here is the most interesting part of firmware analysis, where you'll look for your treasures and discover the common firmware vulnerabilities and how to find them. How to find unencrypted credentials, cryptographic keys, and OS vulnerabilities
Working with firmware analysis could be a very tedious exercise and time consumption. I will explain here how to automate the process of firmware analysis and the pros and cons of using them.
In order to enhance the learning objectives from this chapter, given a firmware the challenge is to unpack it and find vulnerabilities using the tools and techniques learned
The things that can be done with SDR and its large application on IoT devices are amazing. In this session, we'll cover what Software Defined Radio and its application in IoT is
Because SDR requires some specific applications and hardware we got you covered here with this step by step guide to create a SDR lab with OS, applications, and the hardware explanations
Please get familiar with capturing radio signals, transmitting signals, and decoding them. And we will have a very practical session here for playing with those things. You will detect the frequency of a captured signal and its binary code.
In order to enhance the learning objectives from this chapter, given a specific garage door remote your challenge would be to execute a replay attack
Bluetooth Energy is the most popular wireless protocol used on IoT devices and we'll provide an Introduction to bluetooth low energy, how it operates and main components
Hacking BLE require some specific hardware and software. We'll cover here what tools they are and how to use them to capture BLE traffic, and transmit commands to targeted devices
In order to enhance the learning objectives from this chapter, given a specific IoT device that uses BLE your challenge would be to pwning the device
Identify the target Bluetooth device with the HCI tool, capture its MAC address, and use the get tool with Wireshark to observe and change characteristics to unlock the padlock.
Zigbee technology is ubiquitous on IoT devices, and knowing how it works is very important. Here we'll explore Zigbee technology and it's use in IoT for wireless implementation. The range of frequency it normally operates, and explanation of its physical and network layers
Hacking Zigbee is analyzing and decoding its traffic to use the information to exploit it. I'm going to show you tools and techniques used to decode Zigbee traffic and cover both hardware and software requirements.
In order to enhance the learning objectives from this chapter, given a specific IoT device that uses Zigbee your challenge would be to decode it's Zigbee traffic and demonstrate how to exploit it
Reach the end of the IoT pentest course and continue learning with the tools and techniques of this course, testing them on different devices around you.
The IoT Pentes course will familiarize you with standard interfaces in IoT devices and recommend a process along with the Threat Model to evaluate these devices within many layers of the Open Systems Interconnection (OSI) model. From firmware and network protocol analysis to hardware implementation issues and application flaws, we will give you the tools and hands-on techniques to evaluate the ever-expanding range of IoT devices. The course approach facilitates examining the IoT ecosystem across many different verticals, from automotive technology to healthcare, manufacturing, and industrial control systems. The methodology is the same in all cases, but the risk model is different.
The course is efficient, with labs on all modules and a challenge that you offer so you can try to hack a specific device and the solution.
You will learn the following:
Soldering Basics
Hardware Hacking
Using a Multimeter
UART, JTAG, SPIF Interfaces
Firmware Analysis
Binwalk
Software Defined Radio
Analysing Radio Signals
BLE Hacking
Zigbee Hacking
And more!
After finishing this course, you will have a good understanding of IoT security, how to exploit and secure those devices, follow a methodology to approach other devices, and get ready to explore by yourself. Join us in this course, and let's hack the planet!